Dashboards & Visualizations

How to count all created_date and closed_date that lies within specified time picker range?

Nic
Engager

Hi all,

I'm new to Dashboard Studio and I'm running into an issue. I have two dates in my dataset: a created_date and a closed_date. I want to count all created_date that lies in the specified time picker range, and I want to do the same for closed_date.

Splunk automatically creates tokens, $global_time.earliest$ and $global_time.latest$. I tried to compare using these tokens, but this doesn't work:

| eval earliest = $global_time.earliest$
| eval latest = $global_time.latest$
| eval epochcreated_date =strptime(created_date, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where epochcreated_date>= earliest AND epochcreated_date<= latest

I hope someone here can point me in the right direction. Thanks in advance.

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You could try using the times that the search is actually using - these are provided by the addinfo command

| addinfo
| eval epochcreated_date =strptime(created_date, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where epochcreated_date>= info_min_time AND epochcreated_date<= info_max_time

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could try using the times that the search is actually using - these are provided by the addinfo command

| addinfo
| eval epochcreated_date =strptime(created_date, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where epochcreated_date>= info_min_time AND epochcreated_date<= info_max_time
0 Karma

Nic
Engager

Thank you so much!!! This is exactly what I needed, awesome!

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...